tsslib
Easy-to-use threshold signature schemes (TSS) in pure Rust.
tsslib is a Rust port of the broker-based protocols in the Go
tss-lib. The goal is to be wire-
and save-data-compatible with the Go implementation: messages serialized by
one side are consumed by the other, and persisted key shares round-trip across
both languages. All low-level cryptography is provided by
purecrypto — this crate adds no
hand-rolled field arithmetic.
Status: all four protocols implemented. Every scheme below produces signatures that verify under the corresponding stock verifier (Ed25519, ristretto255 Schnorr, secp256k1 ECDSA, FIPS-204 ML-DSA-44). See the per-module notes for which operations are broker-driven vs. in-process.
Protocols
| Module | Scheme | Output | Curve / field |
|---|---|---|---|
frosttss |
FROST(Ed25519, SHA-512) — RFC 9591 | Ed25519 signatures | Edwards25519 |
frostristretto255tss |
FROST(ristretto255, SHA-512) — RFC 9591 | Ristretto255 signatures | ristretto255 |
mldsatss |
Threshold ML-DSA-44 — FIPS 204 | ML-DSA signatures | ML-DSA-44 |
dklstss |
Threshold ECDSA — DKLs23 | ECDSA signatures | secp256k1 |
The FROST protocols and dklstss provide keygen, signing, resharing/refresh,
and HD derivation routed through a caller-supplied [tss::MessageBroker];
dklstss also offers a synchronous in-process API plus offline pre-signing
(presign / sign_with_presign with single-use enforcement). mldsatss
(2 ≤ t ≤ n ≤ 6) provides trusted-dealer keygen, sync + broker-driven threshold
signing, and an experimental dealerless DKG (DkgParty44 — no trusted
dealer; not independently reviewed). Each module is gated behind a like-named
cargo feature, all enabled by default:
[]
= { = "0.1", = false, = ["frosttss"] }
Layout
src/
tss/ core: PartyId, TssError, JsonMessage, MessageBroker
frost/ shared FROST core: ciphersuite, binding, VSS, AEAD, commitments
frosttss/ FROST(Ed25519) keygen · sign · reshare · HD
frostristretto255tss/ FROST(ristretto255) keygen · sign · reshare
mldsatss/ Threshold ML-DSA-44 dealer + DKG keygen · sync/broker sign (+ hyperball)
dklstss/ Threshold ECDSA (DKLs23) sync + broker keygen/sign/reshare/refresh · presign
Security
Peer authentication is out of scope: the broker is trusted to authenticate
message origin (pin peer identities, sign transport messages, reject tampered
bytes). Peer equivocation is caught cryptographically where the protocol
provides an echo-broadcast phase (DKLs keygen/refresh/reshare). The mldsatss
protocol is an academic-grade prototype and is not production-ready.
Cryptography
All low-level cryptography is delegated to purecrypto: the ristretto255 and
Edwards25519 groups + Curve25519 scalar field (FROST), secp256k1 scalar/point
ops (DKLs), and the ML-DSA-44 lattice primitives (mldsa::hazmat: NTT, polynomial
sampling, challenge sampling, bit-packing). tsslib adds no field arithmetic.
Two pieces of protocol logic that are not field arithmetic live here: the
DKLs23 oblivious-transfer stack (Chou-Orlandi base-OT + SoftSpoken/KOS
OT-extension + Gilboa OLE, in dklstss), and the threshold-ML-DSA constant-time
hyperball rejection sampler (a SHAKE256-seeded discrete Gaussian, in
mldsatss/hyperball.rs).
License
MIT — see LICENSE. Portions © 2019 Binance, © 2024 Karpeles Lab Inc.